Security

Top 5: Things to know about FIDO

FIDO is the pathway to nixing passwords. Tom Merritt explains why, because of the FIDO project, this dream is not only possible but getting closer.

Fido is a dog, but FIDO—all caps—is the pathway to the elimination of the password. Imagine it. A world where you no longer have to remember the phrase CorrectHorseBatteryStaple with the es replaced by 3s in order to log in to... anything.

This dream is not only possible but getting closer.

SEE: Information security policy (Tech Pro Research)

Here are five things to know about the FIDO project.

  1. No company owns it. It's a 501(c)6 nonprofit organization formed in July 2012. Organizations like multiple banks, device makers, and telcos around the world have pledged to adopt FIDO, including Samsung, JD.com, China Telecom, Bank of America, Google, Microsoft, Salesforce, and more.
  2. It works to make standards. FIDO is putting its WebAuthn standard for password-free web authentication through the W3C standards process. It hit the Candidate Recommendation stage in April 2018.
  3. It has support. Microsoft is integrating it with Windows Hello. Firefox, Chrome, and Edge all have support in place or on the way. And Apple's Safari engineers are part of the WebAuthn working group under FIDO.
  4. It's simple and flexible. Since the work is done in the browser, it can work with whatever the user has—fingerprint readers or facial recognition or a YubiKey or even something yet to be invented.
  5. It's strong. User credentials do not need to leave the user's device and are never stored on servers. It's a zero-knowledge proof. The app or browser does the work of matching the credential with the service in a way that protects against phishing and man-in-the-middle attacks.

Yes, it takes a lot to make the world's largest companies decide to play nice together on something, but frustration with passwords looks to be the kind of thing that can.

It's a slow kill, but the death of the password is coming.

Also see

About Tom Merritt

Tom is an award-winning independent tech podcaster and host of regular tech news and information shows. Tom hosts Sword and Laser, a science fiction and fantasy podcast, and book club with Veronica Belmont. He also hosts Daily Tech News Show, coverin...

Editor's Picks

Free Newsletters, In your Inbox